





Strong employer brand and metro location but senior specialized role limits applicant density.
High; supply-chain security, AppSec, and CI/CD toolchain expertise are specialized and not easily transferable.
Explicit 11–14 years requirement plus specialized supply-chain security and CI/CD skills makes shortlisting stringent.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Own and execute the software supply chain security strategy to ensure secure-by-default deployment of open source artifacts across the enterprise.
Partner with Engineering leads to implement DevSecOps and AppSec principles, including onboarding application teams to security tools and troubleshooting platform integrations.
Develop, maintain, and communicate supply chain security metrics, documentation, and continuous improvement of DevSecOps and software supply chain security processes and tools.
11 to 14 years of combined experience in development, CI/CD, software supply chain security, and application security.
Bachelor's degree in Computer Science, IT, Information Security, Engineering, or related discipline.
Hands-on experience with application security, build/release management, SSDLC, and automation within CI/CD pipelines.
Hybrid work model requiring 4 days per week at base office location; standard business hours with global stakeholder support.
Deep expertise in software supply chain security, including experience managing artifact caches (e.g., JFrog Artifactory) and knowledge of package ecosystems like Maven Central and PyPI.
Proven ability to influence engineering teams to adopt security best practices and tooling without direct authority, indicating strong cross-functional collaboration skills.
Technical proficiency with programming languages such as Java, .Net, Python, plus experience with cloud (Azure, AWS), automation/orchestration tools, and DevSecOps practices.